← Vulnerability feed

Vulnerability record · CVE-2007-3358 · published 22 June 2007

CVE-2007-3358: SerWeb load_lang.php remote file inclusion allows PHP code execution

Iptel · Serweb

SerWeb 0.9.6 and earlier contains a remote file inclusion flaw in html/load_lang.php, where the _SERWEB[serwebdir] parameter is used to include a remote file without validation. An attacker can point that parameter at a hostile URL and cause the server to execute arbitrary PHP code. The record does not list affected versions beyond '0.9.6 and earlier'.

6.8 CVSS 2.0 Medium EPSS 68% · top 0.7%
6.8CVSS 2.0 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityPublic exploit code and a very high EPSS score make exploitation likely, and the flaw yields remote code execution, though the CVSS 2.0 base score is only 6.8.

What it is

SerWeb 0.9.6 and earlier contains a remote file inclusion flaw in html/load_lang.php, where the _SERWEB[serwebdir] parameter is used to include a remote file without validation. An attacker can point that parameter at a hostile URL and cause the server to execute arbitrary PHP code. The record does not list affected versions beyond '0.9.6 and earlier'.

Impact

Successful exploitation gives the attacker arbitrary PHP code execution in the context of the web server, which typically leads to full compromise of the SerWeb host and any data it can reach. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.

Attack surface

Reachable over the network through HTTP requests to html/load_lang.php; the CVSS vector shows no authentication required (Au:N) and medium access complexity (AC:M). No user interaction is indicated by the description or vector.

Exploitation

Not listed in CISA KEV, but EPSS is 0.68011 (99.3rd percentile) and a public Exploit-DB entry (4089) exists, indicating exploit code is publicly available. No ransomware association is documented.

What to do

  • Upgrade or patch SerWeb to a version later than 0.9.6; the record does not name a fixed release, so confirm with the vendor.
  • If upgrade is not possible, disable or remove html/load_lang.php or restrict access to it.
  • Set PHP allow_url_include and allow_url_fopen to Off so remote URLs cannot be included.
  • Validate and whitelist the _SERWEB[serwebdir] parameter so it cannot contain a URL or path traversal.
  • Isolate the SerWeb host with network controls and least-privilege web server permissions.

Detection

  • Search web logs for requests to html/load_lang.php with a URL or external host in the _SERWEB[serwebdir] parameter.
  • Alert on outbound HTTP requests from the web server to unexpected external hosts, which may indicate remote include fetches.
  • Monitor for unexpected PHP file creation or execution in web-accessible directories on the SerWeb host.
  • Review PHP error logs for include or fopen failures referencing remote URLs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-3358 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2007-3358), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.